[HN Gopher] Yorkshire gang's Game Boy device could unlock car in...
___________________________________________________________________
Yorkshire gang's Game Boy device could unlock car in seconds
Author : giuliomagnifico
Score : 37 points
Date : 2021-10-07 19:02 UTC (3 hours ago)
(HTM) web link (www.bbc.com)
(TXT) w3m dump (www.bbc.com)
| Loughla wrote:
| That is super cool. Not good, obviously. But super cool. I wish
| they had more than just a picture of it, like a video of it
| starting up or something - which I realize would be a bad idea.
|
| I feel like this should be addressed somehow from the
| manufacturer?
| jeroenhd wrote:
| If the device really did look like a gameboy, my guess would be
| that the vendor has an easily brute-force able wireless
| authentication protocol. Several car manufacturers used to
| suffer from this for years, up to quite recently even.
|
| Modern, quality key systems have some protection against plain
| brute forceing, but there are many vehicles out there with
| known vulnerable locks and no way to fix them, at least not for
| free.
|
| I'm convinced that while the thefts are obviously the thiefs'
| fault, the manufacturers play a role in this and should be held
| partially accountable if their software is of the older type
| that consists of little more than a numeric code with no
| further protection, or if the exploit used is already known.
| Either way, a patch should be rolled out to all car owners to
| defeat these attacks because they undoubtedly happen elsewhere.
| Car manufacturers have bolted on wireless keying systems with
| no regards for security for decades now and it's time they
| should be held accountable for their defective systems.
| BuildTheRobots wrote:
| The hardware seems like the least interesting thing from my
| pov. Cramming an SDR and microcontroller/pi into any sort of
| box isn't rocket science. We don't even know if the screen
| works, but if it booted a playable GameBoy emulator then I'd be
| far more interested. Everything built into a cartridge that was
| bootable/playable with a stock GameBoy would really impress...
|
| The bigger question to me, is what they're broadcasting to
| manage this. A targeted MITM or replay attack is one thing, and
| they've been reported in the past. This device seems capable of
| brute forcing in seconds though; and if it's that easy, surely
| the manufacturer is culpable?
|
| Tangentially related to the first point, I wonder if there's
| any Android phone-type devices with a user programmable SDR
| built in. There used to be some handsets with analogue ham
| radios (2m/70cm) so smartphone+sdr seems the next logical step.
| jeroenhd wrote:
| I'm not aware of any SDR smartphones for the commercial
| market. They'd be practically unsellable because of
| regulations anyway. I'm sure you can hide a small SDR board
| into something like a Pinephone, though. You don't need the
| entire frequency range, only the frequencies your targets
| use, so you can cut down significantly on complex parts.
| flatiron wrote:
| Looks like an alliexpress retro knockoff device you get for $40
| that just run android
| blacksmith_tb wrote:
| Very true[1]
|
| 1: https://www.aliexpress.com/item/1005002565595246.html
| contingencies wrote:
| $6 in China.[0] What this actually means is that they reused an
| existing set of polymer injection molds instead of spinning one
| for the project, which has two benefits: 1. Reduced cost. 2.
| Deniability for customers. The second would support a default-
| boot-to-games boot configuration with a secret button push to
| activate real functionality.
|
| Having opened such a device in the recent past (cloned gaming
| type, not the carjacking type) there are seals around the
| buttons so the whole assembly is nontrivial and overly complex
| to reproduce purely for a small-run specialist device.
|
| [0]
| https://detail.tmall.com/item.htm?id=627222036223&skuId=4551...
___________________________________________________________________
(page generated 2021-10-07 23:01 UTC)